You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(pro-auth): move refresh single-flight lock to main (0.3.27)
When two Studio windows are open, each renderer runs its own proLoader
with its own in-flight lock — but those locks don't see each other.
Both windows race on the /refresh POST with the same single-use refresh
token, and the auth service revokes the session as replay. User-visible
symptom: "Your Coherence session expired" within ~15 min of opening
two windows, even right after sign-in.
The lock has to live somewhere only one instance exists, which means
main. Add a `pro-refresh-token` IPC handler that:
- reads the refresh token from the shared secure store
- holds an inFlightProRefresh promise for the duration of the POST
- coalesces concurrent renderer requests onto that promise
- persists new access + rotated refresh tokens atomically
- returns the new access token to all callers
proLoader.refreshAccessToken now delegates to this IPC (keeping its
own per-window lock purely as an optimization) and hydrates its
in-memory caches from the result + disk.
Also bumps to 0.3.27 so the ffmpeg-music fix + this cross-window fix
ship together.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>